Hi Louis,

I understand that the problem is larger than just packetfence, yes.

Reading your email, I'm not sure what to do NOW. Fortunately I had not 
migrated all workstations to 802.1x, just a few to test stability.

However, the mailinglist (you, as well) were major advocates to move in 
that direction. But it seems this has become problematic.

How 'dangerous' would it be to keep ntlm enabled?

MJ

On 04/14/2016 11:45 PM, Louis Munro wrote:
> Hi Mourik,
>
> This is a larger problem than just PacketFence.
> It affects FreeRADIUS in general when authenticating PEAP, or really
> anything that uses ntlm for authentication (Squid and Apache come to
> mind in some configurations).
>
> The following thread is very enlightening on the subject:
> http://freeradius.1045715.n5.nabble.com/NTLMv2-with-FreeRADIUS-td5726394.html
>
> Short answer, you can’t do ntlmv2 with PEAP on FreeRADIUS.
> That said, the eap tunnel is secure from the supplicant to the
> PacketFence server.
>
> Unless someone can intercept and decrypt the traffic from the
> PacketFence server to your AD server a MitM should not be possible.
> Ensuring that unauthorized users/devices cannot have access to that
> traffic is part of the reason why people have a NAC in the first place.
>
> Perfect security would probably require IPsec between PF and the AD server.
> That comes with it’s own set of problems though.
>
> So patch early and patch often (all samba packages as well as your
> Active Directory), and then make sure no one can snoop on the traffic
> between the AD and PacketFence.
>
> It may be we are witnessing the end of the PEAP era.
> EAP-TTLS-PAP and EAP-TLS are not vulnerable to that issue, but their
> support on windows is relatively recent.
>
> Regards,
> --
> Louis Munro
> [email protected] <mailto:[email protected]>  :: www.inverse.ca
> <http://www.inverse.ca>
> +1.514.447.4918 x125  :: +1 (866) 353-6153 x125
> Inverse inc. :: Leaders behind SOGo (www.sogo.nu <http://www.sogo.nu>)
> and PacketFence (www.packetfence.org <http://www.packetfence.org>)
>
>> On Apr 14, 2016, at 10:28 , mj <[email protected]
>> <mailto:[email protected]>> wrote:
>>
>> Hi all,
>>
>> Reading the samba security advisory from two days ago, we were advised
>> to add the smb.conf:
>>
>> server signing = mandatory
>> ntlm auth = no
>>
>> When adding that, the packetfence radius no longer appears to work.
>> (seems logical)
>>
>> But...is there a way to follow the samba security advisory, and at the
>> same time have packetfence with 802.1x security (as advocated on this
>> list) for your networked devices?
>>
>> Or are we forced to choose..?
>
>
>
> ------------------------------------------------------------------------------
> Find and fix application performance issues faster with Applications Manager
> Applications Manager provides deep performance insights into multiple tiers of
> your business applications. It resolves application problems quickly and
> reduces your MTTR. Get your free trial!
> https://ad.doubleclick.net/ddm/clk/302982198;130105516;z
>
>
>
> _______________________________________________
> PacketFence-users mailing list
> [email protected]
> https://lists.sourceforge.net/lists/listinfo/packetfence-users
>

------------------------------------------------------------------------------
Find and fix application performance issues faster with Applications Manager
Applications Manager provides deep performance insights into multiple tiers of
your business applications. It resolves application problems quickly and
reduces your MTTR. Get your free trial!
https://ad.doubleclick.net/ddm/clk/302982198;130105516;z
_______________________________________________
PacketFence-users mailing list
[email protected]
https://lists.sourceforge.net/lists/listinfo/packetfence-users

Reply via email to